{"openapi":"3.1.0","info":{"title":"PUT /api/v1/advisory-firms/{firm_id}/users/{user_id}/menu","version":"1.0.0","description":"Set a firm staff member's sidebar menu"},"servers":[{"url":"https://api.ondayzero.com","description":"Production"}],"paths":{"/api/v1/advisory-firms/{firm_id}/users/{user_id}/menu":{"put":{"tags":["advisory-firms"],"summary":"Set a firm staff member's sidebar menu","description":"Restrict which app sections a firm staff member can reach, either firm-wide or for one client business. Firm staff reach clients *through the firm* and have no membership row there, so the per-membership menu could not be stored for them at all — this is where their menu lives instead. Unlike the per-membership menu, this one is enforced server-side: a request for a section outside the menu is rejected with 403, not merely hidden from the sidebar.","operationId":"set_firm_staff_menu","parameters":[{"name":"firm_id","in":"path","required":true,"schema":{"type":"string","title":"Firm Id"}},{"name":"user_id","in":"path","required":true,"schema":{"type":"string","title":"User Id"}},{"name":"authorization","in":"header","required":false,"schema":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Authorization"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/FirmStaffMenuRequest"}}}},"responses":{"200":{"description":"Successful Response","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessEnvelope_FirmStaffMenuResponse_"}}}},"400":{"description":"Bad Request - Invalid input","content":{"application/json":{"example":{"error":"validation_error","message":"Validation failed: due_date: Input should be a valid date","errors":{"due_date":"Input should be a valid date"},"code":"GEN_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"401":{"description":"Unauthorized - Missing/invalid token or no access to this business","content":{"application/json":{"example":{"error":"unauthorized","message":"Authentication required","code":"AUTH_001","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"403":{"description":"Forbidden - Insufficient permissions","content":{"application/json":{"example":{"error":"forbidden","message":"You don't have permission to access this resource","code":"AUTH_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"404":{"description":"Not Found - Resource does not exist","content":{"application/json":{"example":{"error":"not_found","message":"Resource not found","code":"NOT_FOUND_001","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"},"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"},"example":{"error":"validation_error","message":"Validation failed: amount: Input should be a valid integer","errors":{"amount":"Input should be a valid integer"},"code":"GEN_002","request_id":"3f0e7c2a-9b4d-4e1a-8c6f-2d5b7a1e9c30"}}}}},"x-fastapi-operation-id":"set_firm_staff_menu_api_v1_advisory_firms__firm_id__users__user_id__menu_put"}}},"components":{"schemas":{"FirmStaffMenuRequest":{"properties":{"business_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Business Id","description":"Client business to scope the menu to. Omit or null for the staff member's firm-wide default."},"visible_sections":{"anyOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}],"title":"Visible Sections","description":"Sidebar section keys this staff member may reach. null clears the menu (all sections); an empty list grants none."}},"type":"object","title":"FirmStaffMenuRequest","description":"Request to set a firm staff member's sidebar menu.\n\n``business_id`` None sets the firm-wide default (the only place a menu can\nlive for clients reached via a team grant, or by a firm owner/admin's\nblanket access); a business id sets the override for that one client."},"FirmStaffMenuResponse":{"properties":{"user_id":{"type":"string","title":"User Id"},"firm_id":{"type":"string","title":"Firm Id"},"business_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Business Id"},"visible_sections":{"anyOf":[{"items":{"type":"string"},"type":"array"},{"type":"null"}],"title":"Visible Sections"}},"type":"object","required":["user_id","firm_id"],"title":"FirmStaffMenuResponse","description":"Result of setting a firm staff member's sidebar menu."},"SuccessEnvelope_FirmStaffMenuResponse_":{"properties":{"success":{"type":"boolean","title":"Success","default":true},"message":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Message"},"code":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Code"},"data":{"anyOf":[{"$ref":"#/components/schemas/FirmStaffMenuResponse"},{"type":"null"}]}},"additionalProperties":true,"type":"object","title":"SuccessEnvelope[FirmStaffMenuResponse]"},"ErrorResponse":{"title":"ErrorResponse","type":"object","description":"Envelope returned by every non-2xx response. Branch on `code` (stable) rather than `message` (human-readable, may change).","required":["error","message","code"],"properties":{"error":{"type":"string","description":"Error category: `validation_error`, `unauthorized`, `forbidden`, `not_found`, `conflict`, `rate_limited`, `server_error`, or `service_unavailable`."},"message":{"type":"string","description":"Human-readable explanation, safe to show to end users."},"code":{"type":"string","description":"Stable machine-readable code in `CATEGORY_NNN` form (e.g. `NOT_FOUND_006`, `AUTH_010`, `GEN_002`)."},"request_id":{"type":"string","description":"Correlation id for support requests. Echoes the `x-request-id` request header when one was supplied."},"errors":{"type":"object","additionalProperties":{"type":"string"},"description":"Field-level validation messages keyed by field name. Present on 400/422 validation failures only."}}}},"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"API Token","description":"API token authentication. Format: `Bearer dz_...`"}}},"security":[{"BearerAuth":[]}]}